zeronetworks / rpcfirewallLinks
☆525Updated 4 months ago
Alternatives and similar repositories for rpcfirewall
Users that are interested in rpcfirewall are comparing it to the libraries listed below
Sorting:
- A centralized resource for previously documented WDAC bypass techniques☆575Updated last month
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆336Updated 2 years ago
- Event Tracing For Windows (ETW) Resources☆402Updated last week
- Aims to identify sleeping beacons☆629Updated 10 months ago
- Detect and respond to Cobalt Strike beacons using ETW.☆508Updated 3 years ago
- ☆508Updated last year
- ☆382Updated 2 years ago
- ☆421Updated 3 years ago
- ☆254Updated last year
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆291Updated 2 years ago
- A C# utility for interacting with SCCM☆656Updated last month
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆463Updated last month
- Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for…☆490Updated 2 years ago
- ☆585Updated 4 months ago
- Scan installed EDRs and AVs on Windows☆594Updated 3 months ago
- An effort to track security vendors' use of Microsoft's Antimalware Scan Interface☆249Updated 3 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆981Updated last year
- A PowerShell armoury for security guys and girls☆470Updated last year
- PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.☆320Updated 5 months ago
- ☆202Updated 11 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆774Updated last year
- Sysmon-Like research tool for ETW☆365Updated 2 years ago
- ☆788Updated 2 years ago
- C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.☆420Updated last year
- Project for identifying executables that have command-line options that can be obfuscated, possibly bypassing detection rules.☆177Updated 8 months ago
- Ransomware simulator written in Golang☆449Updated 3 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆156Updated 4 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆855Updated 3 years ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆658Updated 2 years ago